Terms of service & data processing agreement
Last updated: 15 August 2026
These terms govern a merchant's use of StorePulse. Part B is the data processing agreement that applies whenever StorePulse processes personal data on the merchant's behalf, and it takes effect automatically when the app is installed.
A1. The service
StorePulse reads store data from the Shopify Admin API and generates alerts, metrics and email summaries for the merchant. It is a monitoring tool: it reports on the store and does not modify products, orders, inventory or customers. All Shopify permissions requested are read-only.
A2. Acceptable use
The merchant is responsible for keeping their Shopify and StorePulse credentials secure, and for the accuracy of the notification address they configure. The app must not be used to process data for a store the merchant does not control.
A3. Availability and limits
StorePulse depends on Shopify's APIs, scheduled jobs and third-party email delivery. Alerts are provided on a best-effort basis and are not guaranteed to be delivered or to be exhaustive. The merchant remains responsible for operating their store; StorePulse is decision support, not a substitute for the merchant's own checks.
A4. Termination
The merchant may uninstall at any time from the Shopify admin. On uninstall, processing stops immediately and stored data is deleted as described in the privacy policy.
B1. Roles
The merchant is the controller of their customers' personal data. StorePulse is a processor and processes personal data only on the merchant's documented instructions, which for these purposes are the app's configured features.
B2. Scope of processing
- Categories of data subject: the merchant's customers who have placed orders.
- Categories of personal data: customer name and email address, associated with order totals and fulfillment status. No phone numbers, addresses or payment data.
- Purpose: generating store alerts, metrics and summaries for the merchant.
- Duration: for as long as the app is installed, then deleted per the privacy policy.
B3. Our obligations
- Process personal data only for the purposes above, never for our own purposes.
- Apply the technical and organisational measures described on the security page.
- Ensure anyone with access is bound by confidentiality.
- Log access to personal data and retain those logs for audit.
- Assist the merchant in responding to data subject requests, via Shopify's privacy webhooks.
- Delete personal data on uninstall and on redaction requests.
- Notify the merchant without undue delay after becoming aware of a personal data breach.
B4. Subprocessors
StorePulse uses Neon (database hosting), Vercel (application hosting) and Resend (email delivery). Each is engaged under terms consistent with this agreement. Personal data is limited to what is described in B2 — Resend receives the merchant's own notification address, not customer data.
B5. International transfers
Data may be processed in the regions where the above providers operate. Transfers are made under the providers' standard contractual clauses where applicable.